What the vulnerability does
01Description
Missing Authorization vulnerability in SNP Digital SalesKing.This issue affects SalesKing: from n/a through 1.6.15.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
What the vulnerability does
Missing Authorization vulnerability in SNP Digital SalesKing.This issue affects SalesKing: from n/a through 1.6.15.
Explanation of Vulnerability in Simple Terms
SalesKing versions up to 1.6.15 lack proper authorization checks, allowing unauthenticated attackers to modify data and disrupt service. An attacker can send network requests without credentials to alter records or cause the application to become unavailable. No user interaction is required. Update to a version newer than 1.6.15.
What an attacker can do
Modify application data and cause service disruption without authentication.
Potential impact on your site
Unauthorized users can alter business data and cause downtime without needing valid credentials.
Conditions required to exploit
Network access to the SalesKing application; no authentication required.
Key dates
External resources
Related vulnerabilities